<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:18:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:4012 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:4012</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
  * kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free (CVE-2025-38106)
  * kernel: drm/xe: Make dma-fences compliant with the safe access rules (CVE-2025-38703)
  * kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760)
  * kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save (CVE-2025-39818)
  * kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service (CVE-2025-40249)
  * kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)
  * kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)
  * kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097)
  * kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation (CVE-2026-23156)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
  * kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free (CVE-2025-38106)
  * kernel: drm/xe: Make dma-fences compliant with the safe access rules (CVE-2025-38703)
  * kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760)
  * kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save (CVE-2025-39818)
  * kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service (CVE-2025-40249)
  * kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)
  * kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)
  * kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097)
  * kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation (CVE-2026-23156)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:4012</guid>
    </item>
    <item>
      <title>bdu:2026-10187</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10187</link>
      <description>bdu:2026-10187</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10187</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40249</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40249</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0330 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0330</link>
      <description>certfr-2026-avi-0330</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0330</guid>
    </item>
    <item>
      <title>EUVD-2026-347390</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347390</link>
      <description>EUVD-2026-347390</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347390</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40249</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40249</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: cdev: make sure the cdev fd is still active before emitting events&lt;/p&gt;
&lt;p&gt;With the final call to fput() on a file descriptor, the release action
may be deferred and scheduled on a work queue. The reference count of
that descriptor is still zero and it must not be used. It&amp;#39;s possible
that a GPIO change, we want to notify the user-space about, happens
AFTER the reference count on the file descriptor associated with the
character device went down to zero but BEFORE the .release() callback
was called from the workqueue and so BEFORE we unregistered from the
notifier.&lt;/p&gt;
&lt;p&gt;Using the regular get_file() routine in this situation triggers the
following warning:&lt;/p&gt;
&lt;p&gt;struct file::f_count incremented from zero; use-after-free condition present!&lt;/p&gt;
&lt;p&gt;So use the get_file_active() variant that will return NULL on file
descriptors that have been or are being released.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: cdev: make sure the cdev fd is still active before emitting events&lt;/p&gt;
&lt;p&gt;With the final call to fput() on a file descriptor, the release action
may be deferred and scheduled on a work queue. The reference count of
that descriptor is still zero and it must not be used. It&amp;#39;s possible
that a GPIO change, we want to notify the user-space about, happens
AFTER the reference count on the file descriptor associated with the
character device went down to zero but BEFORE the .release() callback
was called from the workqueue and so BEFORE we unregistered from the
notifier.&lt;/p&gt;
&lt;p&gt;Using the regular get_file() routine in this situation triggers the
following warning:&lt;/p&gt;
&lt;p&gt;struct file::f_count incremented from zero; use-after-free condition present!&lt;/p&gt;
&lt;p&gt;So use the get_file_active() variant that will return NULL on file
descriptors that have been or are being released.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40249</guid>
    </item>
    <item>
      <title>GHSA-p8p4-x362-gp65</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p8p4-x362-gp65</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: cdev: make sure the cdev fd is still active before emitting events&lt;/p&gt;
&lt;p&gt;With the final call to fput() on a file descriptor, the release action
may be deferred and scheduled on a work queue. The reference count of
that descriptor is still zero and it must not be used. It&amp;#39;s possible
that a GPIO change, we want to notify the user-space about, happens
AFTER the reference count on the file descriptor associated with the
character device went down to zero but BEFORE the .release() callback
was called from the workqueue and so BEFORE we unregistered from the
notifier.&lt;/p&gt;
&lt;p&gt;Using the regular get_file() routine in this situation triggers the
following warning:&lt;/p&gt;
&lt;p&gt;struct file::f_count incremented from zero; use-after-free condition present!&lt;/p&gt;
&lt;p&gt;So use the get_file_active() variant that will return NULL on file
descriptors that have been or are being released.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: cdev: make sure the cdev fd is still active before emitting events&lt;/p&gt;
&lt;p&gt;With the final call to fput() on a file descriptor, the release action
may be deferred and scheduled on a work queue. The reference count of
that descriptor is still zero and it must not be used. It&amp;#39;s possible
that a GPIO change, we want to notify the user-space about, happens
AFTER the reference count on the file descriptor associated with the
character device went down to zero but BEFORE the .release() callback
was called from the workqueue and so BEFORE we unregistered from the
notifier.&lt;/p&gt;
&lt;p&gt;Using the regular get_file() routine in this situation triggers the
following warning:&lt;/p&gt;
&lt;p&gt;struct file::f_count incremented from zero; use-after-free condition present!&lt;/p&gt;
&lt;p&gt;So use the get_file_active() variant that will return NULL on file
descriptors that have been or are being released.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p8p4-x362-gp65</guid>
    </item>
    <item>
      <title>RHSA-2026:4012 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:4012</link>
      <description>&lt;p&gt;kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting kernel: drm/xe: Make dma-fences compliant with the safe access rules kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kernel: macvlan: fix possible UAF in macvlan_forward_source() kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting kernel: drm/xe: Make dma-fences compliant with the safe access rules kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kernel: macvlan: fix possible UAF in macvlan_forward_source() kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:4012</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40249</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active before emitting events With the final call to fput() on a file descriptor, the release action may be deferred and scheduled on a work queue. The reference count of that descriptor is still zero and it must not be used. It&amp;#39;s possible that a GPIO change, we want to notify the user-space about, happens AFTER the reference count on the file descriptor associated with the character device went down to zero but BEFORE the .release() callback was called from the workqueue and so BEFORE we unregistered from the notifier. Using the regular get_file() routine in this situation triggers the following warning:   struct file::f_count incremented from zero; use-after-free condition present! So use the get_file_active() variant that will return NULL on file descriptors that have been or are being released.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active before emitting events With the final call to fput() on a file descriptor, the release action may be deferred and scheduled on a work queue. The reference count of that descriptor is still zero and it must not be used. It&amp;#39;s possible that a GPIO change, we want to notify the user-space about, happens AFTER the reference count on the file descriptor associated with the character device went down to zero but BEFORE the .release() callback was called from the workqueue and so BEFORE we unregistered from the notifier. Using the regular get_file() routine in this situation triggers the following warning:   struct file::f_count incremented from zero; use-after-free condition present! So use the get_file_active() variant that will return NULL on file descriptors that have been or are being released.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40249</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2747 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2747</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder weitere, nicht spezifizierte Auswirkungen zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder weitere, nicht spezifizierte Auswirkungen zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2747</guid>
    </item>
  </channel>
</rss>
